BSCNE - MICROSOFT AZURE TRACK
Secure Azure Hybrid-Cloud
Network
Capstone Project Proposal
WGU E031 (ITCL 4203) - Task 1
Prepared by [Student Name]
Student ID [Student ID]
Program B.S. Cloud and Network Engineering - Microsoft Azure
Course E031 / ITCL 4203
Submission date [Month Day, Year]
Project sponsor [Simulated Organization / Sponsor]
DOCUMENT USE NOTE
This proposal is an original, customizable model. Replace bracketed fields and reconcile every
requirement with the current official Task 1 rubric and lab constraints before submission.
, Document map
Section Purpose
1. Project overview Business problem, objectives, scope, assumptions
2. Requirements and success Traceable functional, security, operational requirements
criteria
3. On-premises architecture VLANs, addressing, routing, services, firewall zones
4. Azure architecture VNet, subnets, gateway, NSGs, routes, compute
5. Hybrid connectivity VPN resources, cryptographic policy, routing
6. Custom business scenarios Two additional access-control validations
7. Implementation plan Phases, dependencies, change and rollback controls
8. Test and acceptance plan Positive, negative, resiliency, and evidence tests
9. Security, risk, and operations Threats, mitigations, monitoring, sustainability
10. References and appendices Sources, configuration blueprint, evidence checklist
KEY DESIGN DECISION
The proposed networks do not overlap: headquarters uses 192.168.0.0/16 subdivisions; Azure uses
10.100.0.0/16. This prevents ambiguous routing and VPN traffic-selector failures.
Author assumptions and validation gates
The scenario supplied for this model does not include the official evaluation rubric, exact lab topology, assigned public IP
addresses, Azure subscription limits, regional restrictions, or required screenshots. Those values are therefore treated as
validation gates. The student will replace placeholders and obtain course-instructor confirmation before implementation.
Assumption Validation before build
VyOS supports required IKEv2/IPsec and firewall Confirm deployed image/version; adjust commands to that release.
syntax
A public/reachable lab WAN endpoint is available Record actual VyOS WAN IP and NAT behavior.
Azure VPN Gateway SKU supports custom policy Confirm allowed SKU, region, quota, and budget.
ICMP may be restricted by guest OS firewall Use TCP service tests in addition to ping.
Task 1 is a proposal, not proof of completed work Use future tense and reserve implementation evidence for later task.
E031 Task 1 | Azure Hybrid-Cloud Proposal | Customizable Model Page 2
, 1. Project overview and executive summary
1.1 Business problem
The simulated organization currently lacks a defensible method to separate administrative, production, and public-facing
workloads while extending selected services into Microsoft Azure. A flat or weakly controlled network increases
lateral-movement risk, complicates change management, and prevents the organization from applying distinct trust
policies to systems with different business purposes.
1.2 Proposed solution
The project will deploy a proof-of-concept hybrid network. A VyOS appliance in GNS3 will provide 802.1Q subinterfaces,
Layer 3 gateways, stateful zone-based firewall enforcement, network address translation for approved internet egress,
and the on-premises IPsec endpoint. Azure will host a non-overlapping virtual network, a dedicated GatewaySubnet, a
route-based VPN Gateway, a Local Network Gateway representation of the corporate site, subnet-level NSGs, route
controls, and a private application workload.
1.3 Business outcomes
Outcome Measure of success
Reduced lateral movement Unapproved inter-zone tests fail; firewall counters record the denial.
Secure hybrid access Azure reports the S2S connection as Connected and approved application traffic succeeds.
Controlled administration Only VLAN 10 management sources can initiate SSH/RDP to designated systems.
Repeatable validation Every requirement has a named test, expected result, and evidence artifact.
Operational clarity Address plan, diagrams, rule matrix, risks, rollback steps, and ownership are documented.
1.4 Objectives
O1. Segment headquarters into three security zones. O2. route permitted traffic while denying unapproved flows. O3.
connect headquarters and Azure over authenticated, encrypted IPsec/IKEv2. O4. protect the Azure workload with NSGs
and host controls. O5. execute default tests plus two custom business scenarios. O6. preserve reproducible configuration
and evidence.
1.5 Scope
In scope Out of scope
GNS3 topology; VyOS VLAN routing, firewall, NAT, static routes, Production migration; ExpressRoute; global multi-region failover;
VPN; Azure VNet/subnets, VPN resources, NSGs, route tables, test Azure Firewall; third-party SIEM procurement; permanent public
VM; diagrams; validation and documentation. application release; handling real customer data; 24x7 production
support.
E031 Task 1 | Azure Hybrid-Cloud Proposal | Customizable Model Page 3
Secure Azure Hybrid-Cloud
Network
Capstone Project Proposal
WGU E031 (ITCL 4203) - Task 1
Prepared by [Student Name]
Student ID [Student ID]
Program B.S. Cloud and Network Engineering - Microsoft Azure
Course E031 / ITCL 4203
Submission date [Month Day, Year]
Project sponsor [Simulated Organization / Sponsor]
DOCUMENT USE NOTE
This proposal is an original, customizable model. Replace bracketed fields and reconcile every
requirement with the current official Task 1 rubric and lab constraints before submission.
, Document map
Section Purpose
1. Project overview Business problem, objectives, scope, assumptions
2. Requirements and success Traceable functional, security, operational requirements
criteria
3. On-premises architecture VLANs, addressing, routing, services, firewall zones
4. Azure architecture VNet, subnets, gateway, NSGs, routes, compute
5. Hybrid connectivity VPN resources, cryptographic policy, routing
6. Custom business scenarios Two additional access-control validations
7. Implementation plan Phases, dependencies, change and rollback controls
8. Test and acceptance plan Positive, negative, resiliency, and evidence tests
9. Security, risk, and operations Threats, mitigations, monitoring, sustainability
10. References and appendices Sources, configuration blueprint, evidence checklist
KEY DESIGN DECISION
The proposed networks do not overlap: headquarters uses 192.168.0.0/16 subdivisions; Azure uses
10.100.0.0/16. This prevents ambiguous routing and VPN traffic-selector failures.
Author assumptions and validation gates
The scenario supplied for this model does not include the official evaluation rubric, exact lab topology, assigned public IP
addresses, Azure subscription limits, regional restrictions, or required screenshots. Those values are therefore treated as
validation gates. The student will replace placeholders and obtain course-instructor confirmation before implementation.
Assumption Validation before build
VyOS supports required IKEv2/IPsec and firewall Confirm deployed image/version; adjust commands to that release.
syntax
A public/reachable lab WAN endpoint is available Record actual VyOS WAN IP and NAT behavior.
Azure VPN Gateway SKU supports custom policy Confirm allowed SKU, region, quota, and budget.
ICMP may be restricted by guest OS firewall Use TCP service tests in addition to ping.
Task 1 is a proposal, not proof of completed work Use future tense and reserve implementation evidence for later task.
E031 Task 1 | Azure Hybrid-Cloud Proposal | Customizable Model Page 2
, 1. Project overview and executive summary
1.1 Business problem
The simulated organization currently lacks a defensible method to separate administrative, production, and public-facing
workloads while extending selected services into Microsoft Azure. A flat or weakly controlled network increases
lateral-movement risk, complicates change management, and prevents the organization from applying distinct trust
policies to systems with different business purposes.
1.2 Proposed solution
The project will deploy a proof-of-concept hybrid network. A VyOS appliance in GNS3 will provide 802.1Q subinterfaces,
Layer 3 gateways, stateful zone-based firewall enforcement, network address translation for approved internet egress,
and the on-premises IPsec endpoint. Azure will host a non-overlapping virtual network, a dedicated GatewaySubnet, a
route-based VPN Gateway, a Local Network Gateway representation of the corporate site, subnet-level NSGs, route
controls, and a private application workload.
1.3 Business outcomes
Outcome Measure of success
Reduced lateral movement Unapproved inter-zone tests fail; firewall counters record the denial.
Secure hybrid access Azure reports the S2S connection as Connected and approved application traffic succeeds.
Controlled administration Only VLAN 10 management sources can initiate SSH/RDP to designated systems.
Repeatable validation Every requirement has a named test, expected result, and evidence artifact.
Operational clarity Address plan, diagrams, rule matrix, risks, rollback steps, and ownership are documented.
1.4 Objectives
O1. Segment headquarters into three security zones. O2. route permitted traffic while denying unapproved flows. O3.
connect headquarters and Azure over authenticated, encrypted IPsec/IKEv2. O4. protect the Azure workload with NSGs
and host controls. O5. execute default tests plus two custom business scenarios. O6. preserve reproducible configuration
and evidence.
1.5 Scope
In scope Out of scope
GNS3 topology; VyOS VLAN routing, firewall, NAT, static routes, Production migration; ExpressRoute; global multi-region failover;
VPN; Azure VNet/subnets, VPN resources, NSGs, route tables, test Azure Firewall; third-party SIEM procurement; permanent public
VM; diagrams; validation and documentation. application release; handling real customer data; 24x7 production
support.
E031 Task 1 | Azure Hybrid-Cloud Proposal | Customizable Model Page 3